Privacy
Privacy Policy
This Privacy Policy explains how Kin Health AS ("Kin Health", "we", "us", "our"), the company behind Healable, collects and processes personal data when you visit our websites or use the Healable sensitive data workspace. Where your organization has entered into a customer agreement and a data processing agreement with us, those agreements govern the processing of patient and clinical data and take precedence over this policy where they differ.
Who we are
Kin Health AS is the company behind the Healable sensitive data workspace, operated from Norway for healthcare professionals and organizations. Our registered address is Ringveien 36A, 1482 Nittedal, Norway. For any privacy question, or to exercise your rights, contact us at hei@healable.no.
Where your healthcare organization is the controller for patient data, please direct patient-related requests to that organization; we assist as their data processor.
Controller and processor roles
Our role depends on the data in question:
- For our websites, marketing, account administration, and billing, Healable is the data controller.
- For clinical and patient data that a healthcare organization places into a vault, the organization is the controller and Healable is the data processor, acting only on the organization's documented instructions under a data processing agreement.
Personal data we process
Depending on how you interact with us, we may process:
- Account and contact data — name, work email, organization, and role.
- Usage and technical data — log data, device and browser information, IP address, and how the service is used, to keep it secure and reliable.
- Communications — messages you send us, for example when requesting access or support.
- Billing data — limited information needed to process payments; card details are handled by our payment provider, not stored by us.
- Clinical content — health and record material that organizations place into vaults. We process this only as a processor on the controller's instructions.
Why we process data and our legal basis
As a controller, we rely on the following legal bases under the GDPR:
- Performance of a contract — to provide the service, manage accounts, and handle billing.
- Legitimate interests — to secure, maintain, and improve the service, and to communicate about it, balanced against your rights.
- Consent — where required, for example for certain communications; you can withdraw consent at any time.
- Legal obligation — to meet accounting, tax, and other legal requirements.
Health and other special-category data
Healable is built to process sensitive health data only for the intended clinical purpose, inside access-controlled, purpose-bound vaults. When organizations process patient data in the service, Healable acts as their processor under a data processing agreement that defines purpose, categories of data, security measures, sub-processors, and responsibilities. Patients should direct requests about their data to the healthcare provider responsible for their care.
Service providers and sub-processors
We use a small number of vetted providers to run the service, each bound by data-processing terms:
- Google Cloud — hosting and AI processing (including Vertex AI) in EU regions.
- Stripe — payment processing for billing.
- Google Workspace (Gmail) — email and day-to-day business operations.
Where your data is processed
We process personal data within the EU/EEA, on EU cloud regions. We do not transfer personal data outside the EEA. An up-to-date list of sub-processors and processing locations is available on request at hei@healable.no.
How long we keep data
We keep website and account data for as long as needed to provide the service and to meet legal obligations, then delete or anonymize it. Clinical and customer data is retained and deleted according to the customer agreement and the controller's instructions.
Security
Access to data is personal, restricted, and logged for accountability. We use encryption in transit and at rest, access controls, and audit logging, and we limit data handling to the purpose each vault is created for.
Your rights
Subject to applicable law, you have the right to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. To exercise these rights, contact hei@healable.no. If you are in the EEA and believe your data has been handled unlawfully, you may lodge a complaint with your supervisory authority — in Norway, the Norwegian Data Protection Authority (Datatilsynet).
Cookies and analytics
Our websites use only the cookies and similar technologies needed to operate them and to understand aggregate usage. We do not use them to build advertising profiles. You can control cookies through your browser settings.
Changes to this policy
We may update this policy as the service evolves. We will revise the date above when we do, and material changes will be communicated through the service or by email where appropriate.
Privacy, answered
Does Healable need a data processing agreement?
Yes, healthcare organizations should have a data processing agreement before processing patient data in the service.
Can patients' data be put into open chat tools?
Healable is designed as the safer alternative: a dedicated clinical workspace rather than a general-purpose chat tool.
Who can access a vault?
Only authorized users with access to that vault. Access is intended to be logged.